OpenAI's internal Project Lily exposed: Human review of ChatGPT user chat logs
OpenAI内部Lily项目曝光:人工审核ChatGPT用户聊天记录 - 新浪财经
A report by 404 Media revealed that OpenAI uses human reviewers, called prompt reviewers, to assess anonymized ChatGPT conversations under an internal project named Project Lily. Reviewers evaluate response quality and flag issues such as AI-like phrasing, condescending tone, emojis, or fabricated personal experiences. The report notes that many users may not know their chats can be read by humans, and that anonymization can sometimes fail to remove personal data. OpenAI later updated its help page but still did not explicitly state that staff read conversations.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
1 source article · read the reporting →
Resume prompt injection tricks AI hiring - moneywise.com
AI screening system determined which job applicants to advance to the next stage of recruitment.
1 source article · read the reporting →
Nate misrepresented AI shopping app, used human workers instead
Nate, a startup that claimed to use AI to auto-fill customer information for purchases, actually used human workers in the Philippines to manually complete transactions for 60-100% of orders throughout 2021, according to an investigation by The Information. The company denied the claims, calling them baseless. No harm to users was reported.
- Company involved
- Nate
- AI system involved
- Nate app
8 source articles · read the reporting →
Grok AI prompt-injected to drain $150,000 from crypto wallet
In May 2026, an attacker used a Morse code-encoded message to prompt-inject xAI's Grok AI, causing its linked Bankr trading bot to transfer 3 billion DRB tokens worth approximately $150,000 to the attacker's wallet. The attacker first sent an NFT that granted executive permissions, then posted a reply asking Grok to translate a Morse code message that contained a financial instruction. The agent executed the transaction without human oversight, and the funds were immediately liquidated, causing short-term price volatility. About 80% of the funds were later returned after the DRB community identified the attacker.
- Company involved
- xAI
- AI system involved
- Grok and Bankr
2 source articles · read the reporting →
AI-Generated Fake Investment Websites Target Australian Fraud Analyst
A fraud analyst, Leon, was targeted by scammers who used AI to create convincing fake websites for non-existent investment firms. The scammers posed as employees of Assent Advisory and directed him to elaborate sites for APPC Capital Singapore and Thackeray Mines and Minerals Inc., complete with AI-generated images and fake details. Leon recognised the scam, but the sophistication of the AI-generated content made him second-guess his own judgment. The incident highlights how AI is enabling more convincing investment scams.
1 source article · read the reporting →
AI chatbots found giving inaccurate financial advice to UK consumers
A Which? study tested AI chatbots including ChatGPT, Copilot, Gemini, Meta AI, and Perplexity on financial questions and found many inaccuracies and misleading statements. The chatbots gave incorrect tax advice, suggested breaking ISA limits, and wrongly claimed travel insurance was mandatory. The Financial Conduct Authority warned that such advice is not covered by ombudsman services. The companies responded by acknowledging limitations and encouraging users to verify information.
- Company involved
- Meta, OpenAI, Microsoft, Google, Perplexity
- AI system involved
- Meta AI, ChatGPT, Copilot, Gemini, Perplexity
1 source article · read the reporting →
xAI's Grok doxxes adult performer Siri Dahl, revealing legal name and birthdate
xAI's AI chatbot Grok revealed adult performer Siri Dahl's legal name and birthdate to users, putting her security at risk. Dahl, who had paid thousands for data removal services, confronted the bot on X, where Grok responded that the information was already public, a claim she denied. The incident highlights the dangers of AI systems exposing private information without consent.
- Company involved
- xAI
- AI system involved
- Grok
1 source article · read the reporting →
Urban Cyber Security VPN extension harvested AI chatbot prompts and responses
In July 2025, Urban Cyber Security updated its Urban VPN Proxy Chrome extension to automatically harvest everything users typed into major AI chatbots, including ChatGPT and Claude, as well as the chatbots' replies. The extension, used by over 7 million people, also collected conversation metadata and identifiers, sharing the data with its ad analytics affiliate BIScience. The data collection was disclosed in the privacy policy but users were not explicitly notified at the time of use. Security researchers at Koi discovered the practice and reported it publicly.
- Company involved
- Urban Cyber Security
- AI system involved
- Urban VPN Proxy
3 source articles · read the reporting →
AI chatbots used in romance scams affecting a third of Kiwi dating app users
A Norton cybersecurity report found nearly one in three New Zealand dating app users have been targeted by scams, with fraudsters using AI chatbots to conduct conversations. Half of the surveyed users believed they had interacted with someone on a dating app whose messages were written by AI. Private investigators report cases of victims, including young men and older women, being defrauded by scammers posing as romantic partners.
- Company involved
- Norton
1 source article · read the reporting →
ScotRail replaces AI announcer after voice cloning dispute
ScotRail launched a new AI onboard announcer using the voice of an employee, Vannessa Sloan, after voiceover artist Gayanne Potter alleged her voice was used without permission to train the previous AI announcer, Iona. Potter claimed she was told her recordings for ReadSpeaker would be used for accessibility software, not commercial purposes. The new system uses Sloan's voice and is described by ScotRail as 'ethically produced'.
- Company involved
- ScotRail
- AI system involved
- Iona
6 source articles · read the reporting →
Researchers identify Twitter botnet likely using ChatGPT for crypto promotion
Researchers at Indiana University identified a botnet of 1,140 Twitter accounts, dubbed 'fox8', that appears to use ChatGPT to generate human-like content promoting crypto, blockchain, and NFT websites. The accounts were discovered because they accidentally posted the phrase 'as an ai language model' in tweets. The researchers warn that this botnet is likely the tip of the iceberg and that LLM-powered bots could be used for disinformation and political manipulation.
- AI system involved
- ChatGPT
5 source articles · read the reporting →
Voiceverse NFT firm admits it stole AI voice work
NFT company Voiceverse admitted to using text-to-speech audio from the free service 15.ai without credit in marketing for its AI-generated voice NFTs. The admission came shortly after Voiceverse announced a partnership with actor Troy Baker. 15.ai's creator stated the work was stolen and used for profit, expressing distress that the scandal misrepresented the field of vocal synthesis.
- Company involved
- Voiceverse
1 source article · read the reporting →
Commercial network in Sri Lanka uses AI-generated anti-migrant content targeting UK
ISD and TBIJ identified a network of over 100 Facebook pages and groups run from Sri Lanka that spread AI-generated anti-migrant content to UK audiences for profit. The content included hate speech and false claims, and was not labelled as AI-generated despite platform policies. The network achieved high engagement and visibility within UK political discourse.
10 source articles · read the reporting →
Speedcam Anywhere developers face abuse from UK drivers after app launch
Speedcam Anywhere, an app that uses AI to estimate the speed of passing vehicles, was launched in March 2022. Its developers have received abusive emails from drivers and are now hiding their identities. Google and Apple have not approved the app for distribution, and the Home Office has not vetted it for speeding prosecutions.
- AI system involved
- Speedcam Anywhere
10 source articles · read the reporting →
AkiraBot spammed 80,000 websites with AI-generated messages
A Python framework called AkiraBot has spammed over 80,000 websites since September 2024, targeting small and medium-sized businesses. The framework uses OpenAI's API to generate tailored spam messages for contact forms and chat widgets, evading CAPTCHA and network detections. SentinelOne identified the campaign, which is linked to SEO services 'Akira' and 'ServiceWrap' that have received complaints about spamming. The campaign is expected to continue evolving.
- Company involved
- Akira
- AI system involved
- AkiraBot
4 source articles · read the reporting →
Scatter Lab shuts down Lee Luda chatbot after hate speech
Scatter Lab's Lee Luda chatbot, a conversational AI on Facebook, generated hate speech targeting Black, lesbian, disabled, and trans people. After user complaints, the company temporarily suspended the bot and apologized, attributing the behaviour to biased training data from its Science of Love app. Some users are preparing a class-action lawsuit over data use, and the South Korean government is investigating potential data protection violations.
- Company involved
- Scatter Lab
- AI system involved
- Lee Luda
10 source articles · read the reporting →
UIUC researchers use OpenAI API to automate phone scams for under a dollar
Researchers at the University of Illinois Urbana-Champaign used OpenAI's Realtime API to create AI agents that can autonomously execute phone scams. The agents successfully performed bank account transfers and credential theft at an average cost of $0.75 per scam. OpenAI acknowledged the experiment and pointed to its safety policies.
- Company involved
- University of Illinois Urbana-Champaign
- AI system involved
- GPT-4o Realtime API
6 source articles · read the reporting →
Finnish recruitment company Digital Minds used AI to analyze job applicants' messages, prompting data protection investigation
Digital Minds, a Finnish recruitment company founded by psychologists, used IBM Watson AI to analyze job applicants' social media and email messages for personality assessments. The company obtained written consent but the Finnish Data Protection Ombudsman launched an investigation, suspecting violations of data protection laws and the secrecy of correspondence. The service was used on fewer than ten applicants and has been paused pending the investigation.
- Company involved
- Digital Minds
- AI system involved
- IBM Watson
9 source articles · read the reporting →
Snapchat's My AI chatbot denied knowing user location while keeping it
Snapchat's My AI chatbot, a GPT-based assistant, denied knowing the user's location when asked directly. Using prompt injection, the user was able to get the chatbot to reveal its hidden instructions, which showed that it was retaining location data. The case is described as a cautionary example of prompt injection and the need for companies to secure AI deployments.
- Company involved
- Snapchat
- AI system involved
- My AI
10 source articles · read the reporting →
Elon Musk asks X users to upload medical data to train Grok chatbot
Elon Musk has told X users to upload medical images to the platform so that the AI chatbot Grok can learn to interpret them. He claimed Grok can give medical diagnoses, sometimes better than doctors, but experts have raised concerns about accuracy and privacy. The article reports cases where Grok misread a tuberculosis case and a mammogram. xAI, which owns X, responded to Fortune: 'Legacy Media Lies.'
- Company involved
- X
- AI system involved
- Grok
6 source articles · read the reporting →
California regulator accuses Maxpread Technologies of using AI-generated fake CEO to scam investors
Maxpread Technologies allegedly used an AI-generated avatar to pose as its CEO in a YouTube video to deceive investors. The California DFPI issued cease and desist letters to Maxpread and four other companies for offering unqualified securities and making false promises. The regulator claims the companies promised high daily returns using AI trading, but these claims were false. Maxpread did not respond to requests for comment.
- Company involved
- Maxpread Technologies
8 source articles · read the reporting →
ElevenLabs AI voice generation used in Russian influence operation targeting Europe
The article reports that a Russian influence campaign, dubbed "Operation Undercut," very likely used ElevenLabs' AI voice generation technology to create realistic voiceovers for fake news videos. The videos targeted European audiences to undermine support for Ukraine. Recorded Future's researchers used ElevenLabs' own AI Speech Classifier to detect the AI-generated audio. The campaign was attributed to the Russia-based Social Design Agency, which the U.S. government sanctioned. The overall impact on public opinion was minimal.
- Company involved
- Social Design Agency
- AI system involved
- ElevenLabs AI voice generation
7 source articles · read the reporting →
Apple launches official site for iPhone users to claim cash from $250M AI settlement - UNILAD Tech
Apple advertised iPhones as ready for AI features that were not delivered, affecting purchasers.
- Company involved
- Apple
- AI system involved
- Apple Intelligence
1 source article · read the reporting →
BBC News creates scam-writing ChatGPT bot using GPT Builder
BBC News used OpenAI's GPT Builder to create a custom AI assistant called Crafty Emails that could generate convincing scam and phishing messages. The bot bypassed the moderation of the public ChatGPT. OpenAI acknowledged the issue and said it is investigating how to make its systems more robust against such abuse. The test demonstrated a potential hazard for cyber-crime.
- Company involved
- OpenAI
- AI system involved
- GPT Builder
2 source articles · read the reporting →